Directory traversal vulnerability in the download feature in Cybozu Garoon 2.x through 2.5.4 and 3.x through 3.7 SP3 allows remote authenticated users to read arbitrary files via unspecified vectors.Referenceshttp://jvn.jp/en/jp/JVN26393529/index.htmlhttp://cs.cybozu.co.jp/information/gr20140225up05.phphttp://jvndb.jvn.jp/jvndb/JVNDB-2014-000023https://support.cybozu.com/ja-jp/article/7994http://www.securityfocus.com/bid/65815